RETIRED: X.Org X Server Local Privilege Escalation and Information Disclosure Vulnerabilities
BID:27336
Info
RETIRED: X.Org X Server Local Privilege Escalation and Information Disclosure Vulnerabilities
| Bugtraq ID: | 27336 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 17 2008 12:00AM |
| Updated: | Jan 18 2008 09:28PM |
| Credit: | regenrecht, Takuya Shizaki of CERT/CC and an anonymous researcher are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
X.org Xserver 1.3 X.org xorg-server 1.4 X.org xorg-server 1.3.99.2 (RC2) X.org xorg-server 1.2 X.org xorg-server 1.02-r5 X.org xorg-server 1.0.2-r6 X.org X11R7 1.1.1 X.org X11R7 1.0.2 X.org X11R7 1.0.1 X.org X11R7 1.0 X.org X11R7 7.2 X.org X11R7 7.1 X.org X11R7 7.0 X.org X11R6 6.9 X.org X11R6 6.8.2 X.org X11R6 6.8.1 X.org X11R6 6.8 X.org X11R6 6.7 .0 X.org X11R6 5.1 X.org X11R6 4.0 X.org LibXfont 1.3.1 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE Linux Enterprise Server 10.SP1 SuSE Linux Enterprise Server 10 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux Virtualization 5 Server Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
X.org xorg-server 1.4.1 |
Discussion
RETIRED: X.Org X Server Local Privilege Escalation and Information Disclosure Vulnerabilities
X.Org X Server is prone to multiple local privilege-escalation vulnerabilities and an information-disclosure vulnerability.
Attackers can exploit these issues to execute arbitrary code with superuser privileges, crash the affected computer, or obtain potentially sensitive information.
NOTE: This BID is being retired because each of the vulnerabilities has been given its own record as follows:
27350 X.Org X Server 'MIT-SHM' Local Privilege Escalation Vulnerability
27351 X.Org X Server 'Xinput' Extension Local Privilege Escalation Vulnerability
27352 X.Org X Server PCF Font Parser Buffer Overflow Vulnerability
27353 X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerability
27354 X.Org X Server 'PassMessage' Request Local Privilege Escalation Vulnerability
27355 X.Org X Server 'TOG-CUP' Extension Local Privilege Escalation Vulnerability
27356 X.Org X Server X:1 -sp Command Information Disclosure Vulnerability
X.Org X Server is prone to multiple local privilege-escalation vulnerabilities and an information-disclosure vulnerability.
Attackers can exploit these issues to execute arbitrary code with superuser privileges, crash the affected computer, or obtain potentially sensitive information.
NOTE: This BID is being retired because each of the vulnerabilities has been given its own record as follows:
27350 X.Org X Server 'MIT-SHM' Local Privilege Escalation Vulnerability
27351 X.Org X Server 'Xinput' Extension Local Privilege Escalation Vulnerability
27352 X.Org X Server PCF Font Parser Buffer Overflow Vulnerability
27353 X.Org X Server 'EVI' Extension Local Privilege Escalation Vulnerability
27354 X.Org X Server 'PassMessage' Request Local Privilege Escalation Vulnerability
27355 X.Org X Server 'TOG-CUP' Extension Local Privilege Escalation Vulnerability
27356 X.Org X Server X:1 -sp Command Information Disclosure Vulnerability
Exploit / POC
RETIRED: X.Org X Server Local Privilege Escalation and Information Disclosure Vulnerabilities
Currently we are not aware of any exploits for the privilege-escalation issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for the privilege-escalation issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: X.Org X Server Local Privilege Escalation and Information Disclosure Vulnerabilities
Solution:
The vendor released an update and an advisory to address these issues. Please see the references for more information.
X.org xorg-server 1.2
X.org xorg-server 1.4
X.org LibXfont 1.3.1
Solution:
The vendor released an update and an advisory to address these issues. Please see the references for more information.
X.org xorg-server 1.2
-
X.org xorg-xserver-1.2-multiple-overflows.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.2/patches/xorg-xserver-1.2-mu ltiple-overflows.diff
X.org xorg-server 1.4
-
X.org xorg-xserver-1.4-multiple-overflows.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-xserver-1.4-mu ltiple-overflows.diff
X.org LibXfont 1.3.1
-
X.org xorg-libXfont-1.3.1-pcf-parser.diff
ftp://ftp.freedesktop.org/pub/xorg/X11R7.3/patches/xorg-libXfont-1.3.1 -pcf-parser.diff
References
RETIRED: X.Org X Server Local Privilege Escalation and Information Disclosure Vulnerabilities
References:
References:
- Multiple Vendor X Server EVI and MIT-SHM Extensions Integer Overflow (iDefense Labs)
- Multiple Vendor X Server TOG-CUP Extension Information Disclosure Vulnerability (iDefense Labs)
- Multiple Vendor X Server XFree86-Misc Extension Invalid Array Index (iDefense Labs)
- Multiple Vendor X Server XInput Extension Multiple Memory Corruption (iDefense Labs)
- X.Org Homepage (X.Org)
- iDefense Security Advisory 01.17.08: Multiple Vendor X Server EVI and MIT-SHM (iDefense Labs
) - iDefense Security Advisory 01.17.08: Multiple Vendor X Server TOG-CUP Extension (iDefense Labs
) - iDefense Security Advisory 01.17.08: Multiple Vendor X Server XFree86-Misc Exten (iDefense Labs
) - iDefense Security Advisory 01.17.08: Multiple Vendor X Server XInput Extension M ([email protected])
- RHSA-2008:0029-9 XFree86 security update (Red Hat)
- RHSA-2008:0030-7 xorg-x11 security update (Red Hat)
- RHSA-2008:0031-8 xorg-x11-server security update (Red Hat)
- RHSA-2008:0064-5 libXfont security update (Red Hat)
- Sun Alert ID: 103192 A Security Vulnerability in the Solaris X Window System (X( (Sun)
- Sun Alert ID: 103200 Multiple Security Vulnerabilities in the Solaris X Server E (Sun)
- Sun Alert ID: 103205 Security Vulnerability in the Solaris X Server May Lead to (Sun)
- X.Org security advisory, January 17th, 2008 (X.Org)